7.5

CVE-2002-1654

Exploit

iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.

Data is provided by the National Vulnerability Database (NVD)
IplanetIplanet Web Server Version6.0
IplanetIplanet Web Server Versionenterprise_4.0
IplanetIplanet Web Server Versionenterprise_4.1
NetscapeEnterprise Server Version2.0
NetscapeEnterprise Server Version3.0
NetscapeEnterprise Server Version3.1
NetscapeEnterprise Server Version3.2
NetscapeEnterprise Server Version3.3
NetscapeEnterprise Server Version3.4
NetscapeEnterprise Server Version3.5
NetscapeEnterprise Server Version3.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.78% 0.81
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P